DETECTION OVERVIEW
Risk Factors
Devices running Invati Sentry are typically internet-facing, and this vulnerability affects many versions of Sentry. An attacker can exploit this vulnerability with public code to gain complete control of a device.
Category

Ivanti Sentry, formerly known as MobileIron Core, is a gateway for mobile devices. An authentication bypass vulnerability exists in the System Manager Portal because of an Apache HTTPD misconfiguration. This vulnerability enables unauthenticated attackers to remotely run commands through the administrative web UI on port 8443. To exploit this vulnerability, an attacker sends an HTTPS POST request to the /mics/services/MICSLogService API endpoint with the malicious command in the HTTP request body.
Network analysis and visibility solutions remain underrepresented in enterprises. Find out why in this preview of a new Wave report.
ExtraHop® Named a Leader in First-Ever Gartner® Magic Quadrant™ for Network Detection and Response
Visit this resource for more information.
This analysis exposes the critical link between an organization's lack of internal visibility and the escalating cost of compromise, demanding an urgent re-evaluation of how core business assets are protected.
Learn why you need to be wary of the claims certain network detection and response providers make about their coverage against the MITRE ATT&CK framework.
Learn how NDR from RevealX helps security teams detect and investigate more adversary TTPs in the MITRE ATT&CK framework than rule-based tools.
